Amazon confirmed a data exposure affecting internal employee directories. A threat actor exploited a vulnerability in a third-party property management system to exfiltrate corporate contact information, including employee work email addresses, desk phone numbers, and building locations. No customer or financial data was compromised.